DevOps with Kubernetes accelerating software delivery with container orchestrators (Hideto Saito, Hui-Chuan Chloe Lee etc.)(Z-Library)
DevOps
No Description
93
Views
0
Downloads
0.00
Total Donations
Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Page
1
(This page has no text content)
Page
2
DevOps with Kubernetes Accelerating software delivery with container orchestrators
Page
3
Hideto Saito Hui-Chuan Chloe Lee Cheng-Yang Wu BIRMINGHAM - MUMBAI
Page
4
DevOps with Kubernetes Copyright © 2017 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the authors, nor Packt Publishing, and its dealers and distributors will be held liable for any damages caused or alleged to be caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. First published: October 2017 Production reference: 1121017 Published by Packt Publishing Ltd. Livery Place 35 Livery Street Birmingham B3 2PB, UK. ISBN 978-1-78839-664-6
Page
5
www.packtpub.com
Page
6
Credits Authors Hideto Saito Hui-Chuan Chloe Lee Cheng-Yang Wu Copy Editors Laxmi Subramanian Safis Editing Reviewer Guang Ya Liu Project Coordinator Shweta H Birwatkar Proofreader Safis Editing Commissioning Editor Gebin George
Page
7
Acquisition Editor Chandan Kumar Indexer Pratik Shirodkar Content Development Editor Dattatraya More Graphics Tania Dutta Technical Editor Jovita Alva Production Coordinator Shantanu Zagade
Page
8
About the Authors Hideto Saito has around 20 years of experience in the computer industry. In 1998, while working for Sun Microsystems Japan, he was impressed with Solaris OS, OPENSTEP, and Sun Ultra Enterprise 10000 (AKA StarFire). Then, he decided to pursue the UNIX and MacOS X operation systems. In 2006, he relocated to southern California as a software engineer to develop products and services running on Linux and MacOS X. He was especially renowned for his quick Objective-C coding when he was drunk. He is also an enthusiastic fan of Japanese anime, drama, and motor sports, and loves Japanese Otaku culture. Hui-Chuan Chloe Lee is a DevOps and software developer. She has worked in the software industry on a wide range of projects for over 5 years. As a technology enthusiast, Chloe loves trying and learning new technologies, which makes her life happier and more fulfilled. In her free time, she enjoys reading, traveling, and spending time with the people she loves. Cheng-Yang Wu has been tackling infrastructure and system reliability since he received his master’s degree in computer science from the National Taiwan University. His laziness prompted him to master DevOps skills to maximize his efficiency at work in order to squeeze in writing code for fun. He enjoys cooking as it's just like working with software—a perfect dish always comes from balanced flavors and fine-tuned tastes.
Page
9
About the Reviewer Guang Ya Liu is a Senior Software Architect in IBM CSL (China System Lab) and now focuses on cloud computing, data center operating systems and container technology, he is also a Member of IBM Academy of Technology. He used to be a OpenStack Magnum Core Member from 2015 to 2017, and now act as Kubernetes Member and Apache Mesos Committer & PMC Member. Guang Ya is also the organizer for Mesos, Kubernetes and OpenStack Xi'an Meetup and successfully held many meetups for those open source projects in China. He also holds two US patents related to cloud and six publised IPs. Visit his GitHub here: https://github.com/gyliu513.
Page
10
www.PacktPub.com For support files and downloads related to your book, please visit www.PacktPub.com. Did you know that Packt offers eBook versions of every book published, with PDF and ePub files available? You can upgrade to the eBook version at www.PacktPub.com and as a print book customer, you are entitled to a discount on the eBook copy. Get in touch with us at service@packtpub.com for more details. At www.PacktPub.com, you can also read a collection of free technical articles, sign up for a range of free newsletters and receive exclusive discounts and offers on Packt books and eBooks. https://www.packtpub.com/mapt Get the most in-demand software skills with Mapt. Mapt gives you full access to all Packt books and video courses, as well as industry-leading tools to help you plan your personal development and advance your career.
Page
11
Why subscribe? Fully searchable across every book published by Packt Copy and paste, print, and bookmark content On demand and accessible via a web browser
Page
12
Customer Feedback Thanks for purchasing this Packt book. At Packt, quality is at the heart of our editorial process. To help us improve, please leave us an honest review on this book's Amazon page at https://www.amazon.com/dp/1788396642. If you'd like to join our team of regular reviewers, you can email us at customerreviews@packtpub.com. We award our regular reviewers with free eBooks and videos in exchange for their valuable feedback. Help us be relentless in improving our products!
Page
13
Table of Contents Preface What this book covers What you need for this book Who this book is for Conventions Reader feedback Customer support Downloading the example code Downloading the color images of this book Errata Piracy Questions 1. Introduction to DevOps Software delivery challenges Waterfall and physical delivery Agile and electrical delivery Software delivery on the cloud Continuous Integration Continuous Delivery Configuration management Infrastructure as code Orchestration Trend of microservices Modular programming Package management MVC design pattern Monolithic application Remote Procedure Call RESTful design Microservices Automation and tools Continuous Integration tool Continuous Delivery tool Monitoring and logging tool Communication tool Public cloud Summary
Page
14
2. DevOps with Container Understanding container Resource isolation Linux container concept Containerized delivery Getting started with container Installing Docker for Ubuntu Installing Docker for CentOS Installing Docker for macOS Container life cycle Docker basics Layer, image, container, and volume Distributing images Connect containers Working with Dockerfile Writing your first Dockerfile Dockerfile syntax Organizing a Dockerfile Multi-containers orchestration Piling up containers Docker Compose overview Composing containers Summary 3. Getting Started with Kubernetes Understanding Kubernetes Kubernetes components Master components API server (kube-apiserver) Controller Manager (kube-controller-manager) etcd Scheduler (kube-scheduler) Node components Kubelet Proxy (kube-proxy) Docker Interaction between Kubernetes master and nodes Getting started with Kubernetes Preparing the environment kubectl Kubernetes resources Kubernetes objects
Page
15
Namespace Name Label and selector Annotation Pods ReplicaSet (RS) and ReplicationController (RC) Deployments Services Volumes Secrets ConfigMap Using ConfigMap via volume Using ConfigMap via environment variables Multi-containers orchestration Summary 4. Working with Storage and Resources Kubernetes volume management Container volume lifecycle Sharing volume between containers within a pod Stateless and stateful applications Kubernetes Persistent Volume and dynamic provisioning Persistent Volume claiming the abstraction layer Dynamic Provisioning and StorageClass A problem case of ephemeral and persistent setting Replicating pods with a Persistent Volume using StatefulSet Persistent Volume example Elasticsearch cluster scenario Elasticsearch master node Elasticsearch master-eligible node Elasticsearch data node Elasticsearch coordinating node Kubernetes resource management Resource Quality of Service Configuring the BestEffort pod Configuring as the Guaranteed pod Configuring as Burstable pod Monitoring resource usage Summary 5. Network and Security Kubernetes networking
Page
16
Docker networking Container-to-container communications Pod-to-pod communications Pod communication within the same node Pod communication across nodes Pod-to-service communications External-to-service communications Ingress Network policy Summary 6. Monitoring and Logging Inspecting a container Kubernetes dashboard Monitoring in Kubernetes Application Host External resources Container Kubernetes Getting monitoring essentials for Kubernetes Hands-on monitoring Meeting Prometheus Deploying Prometheus Working with PromQL Discovering targets in Kubernetes Gathering data from Kubernetes Seeing metrics with Grafana Logging events Patterns of aggregating logs Collecting logs with a logging agent per node Running a sidecar container to forward logs Ingesting Kubernetes events Logging with Fluentd and Elasticsearch Extracting metrics from logs Summary 7. Continuous Delivery Updating resources Triggering updates Managing rollouts Updating DaemonSet and StatefulSet DaemonSet
Page
17
StatefulSet Building a delivery pipeline Choosing tools Steps explained env script after_success deploy Gaining deeper understanding of pods Starting a pod Liveness and readiness probes Init containers Terminating a pod Handling SIGTERM SIGTERM is not forwarded to the container process SIGTERM doesn't invoke the termination handler Container lifecycle hooks Placing pods Summary 8. Cluster Administration Kubernetes namespaces Default namespaces Create a new namespace Context Create a context Switch the current context ResourceQuota Create a ResourceQuota for a namespace Request pods with default compute resource limits Delete a namespace Kubeconfig Service account Authentication and authorization Authentication Service account authentication User account authentication Authorization Attribute-based access control (ABAC) Role-based access control (RBAC) Roles and ClusterRoles RoleBinding and ClusterRoleBinding Admission control
Page
18
Namespace life cycle LimitRanger Service account PersistentVolumeLabel DefaultStorageClass ResourceQuota DefaultTolerationSeconds Taints and tolerations PodNodeSelector AlwaysAdmit AlwaysPullImages AlwaysDeny DenyEscalatingExec Other admission controller plugins Summary 9. Kubernetes on AWS Introduction to AWS Public cloud API and infrastructure as code AWS components VPC and subnet Internet gateway and NAT-GW Security group EC2 and EBS Route 53 ELB S3 Setup Kubernetes on AWS Install kops Run kops Kubernetes cloud provider L4 LoadBalancer L7 LoadBalancer (ingress) StorageClass Maintenance Kubernetes cluster by kops Summary 10. Kubernetes on GCP Introduction to GCP GCP components VPC Subnets
Page
19
Firewall rules VM instance Load balancing Health check Backend service Creating a LoadBalancer Persistent Disk Google Container Engine (GKE) Setting up your first Kubernetes cluster on GKE Node pool Multi zone cluster Cluster upgrade Kubernetes cloud provider StorageClass L4 LoadBalancer L7 LoadBalancer (ingress) Summary 11. What's Next Exploring the possibilities of Kubernetes Mastering Kubernetes Job and CronJob Affinity and anti-affinity between pods and nodes Auto-scaling of pods Prevention and mitigation of pod disruptions Kubernetes federation Cluster add-ons Kubernetes and communities Kubernetes incubator Helm and charts Gravitating towards a future infrastructure Docker swarm mode Amazon EC2 container service Apache Mesos Summary
Page
20
Preface This book walks you through a journey of learning fundamental concept and useful skills for DevOps, containers and Kubernetes.
The above is a preview of the first 20 pages. Register to read the complete e-book.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
# DevOps with Kubernetes: Accelerating Software Delivery with Container Orchestrators
## 【One-Line Pitch】
A practical, hands-on guide for developers and ops engineers who want to master containerized application delivery by combining DevOps practices with Kubernetes orchestration—covering everything from Docker fundamentals to cluster administration and cloud deployment.
## 【Book Arc】
- **Opening (~0%–10%)**: Introduces the software delivery challenges that motivate DevOps, explains infrastructure as code concepts, and covers configuration management tools like Chef and AWS CloudFormation. Establishes why automation and version-controlled infrastructure are essential for modern delivery.
- **Early (~10%–23%)**: Dives into Docker fundamentals—images, containers, namespaces, resource isolation, Dockerfile instructions (COPY, ADD, VOLUME), and Docker Compose for multi-container orchestration. Builds the container foundation needed before Kubernetes makes sense.
- **Early (~23%–39%)**: Introduces Kubernetes architecture (Masters and Nodes, kube-proxy), then walks through core objects: Pods, ReplicationControllers, ReplicaSets, Deployments, Services (ClusterIP, NodePort, LoadBalancer), Secrets, and ConfigMaps. Includes a complete kiosk application deployment example that ties concepts together.
- **Middle (~39%–48%)**: Covers persistent storage with Kubernetes Volumes, PersistentVolumes, StorageClass, and dynamic provisioning across cloud providers (AWS EBS, GCP Persistent Disk). Also explains resource QoS classes (BestEffort, Burstable, Guaranteed) and how to configure pods for different priority levels.
- **Late (~48%–end)**: Explores networking in depth—how LoadBalancer traffic routes to pods across nodes, service-to-pod communication patterns, and network policies (using Calico as an example). The book then moves to cluster administration topics: namespaces, ResourceQuota, kubeconfig, service accounts, authentication/authorization (ABAC, RBAC), and admission control.
## 【Key Takeaways】
- **Infrastructure as code is the foundation of DevOps** (Opening): Managing infrastructure through version-controlled configuration files (rather than manual SOP documents) enables history tracking, easy duplication, and eliminates human error in environment setup. Tools like Chef and CloudFormation automate what was once manual cloud operations.
- **Containers are instances of immutable images** (Early): An image bundles code, libraries, and configuration; a container is the runtime instance. Understanding the difference—and using commands like `docker inspect`, `exec`, and `attach`—is essential before moving to orchestration.
- **Dockerfile instructions have specific behaviors** (Early): COPY and ADD both move files into images, but ADD also handles URLs and compressed files. VOLUME creates data volumes at build time, but host directory mounting isn't possible in Dockerfiles due to portability concerns—a limitation that Kubernetes volumes later solve.
- **Docker Compose is a medley of Docker functions** (Early): The `up` command is the closest counterpart to `docker run`, and Compose handles networks, volumes, and services defined in YAML. It's the bridge between single-container Docker and multi-container orchestration.
- **Kubernetes controllers enforce desired state** (Early): ReplicationControllers and ReplicaSets continuously monitor pod counts and evict or create pods to match specifications. ReplicaSets use set-based selectors (matchLabels, matchExpressions) and should always be managed by Deployments, not created directly.
- **Persistent storage requires planning for scalability** (Middle): StatefulSet with PersistentVolume requires Dynamic Provisioning and StorageClass because Kubernetes must know how to provision new volumes when scaling pods. Cloud providers (AWS, GCP) create default StorageClasses, but administrators should verify configurations.
- **Resource QoS classes determine pod priority** (Middle): BestEffort pods (no resource limits) are terminated first during shortages—ideal for stateless, recoverable workloads like workers or caches. Namespace default resource settings can override implicit BestEffort configuration, so explicit settings are safer.
- **LoadBalancer routing has cross-node overhead** (Late): Cloud LoadBalancers are node-aware, not pod-aware. Packets may arrive at nodes without the target pod, requiring additional routing hops. Understanding this journey (LoadBalancer → node → service → pod) helps design efficient service architectures.
## 【Reading Tips】
- **Skim the opening chapters** (~0–10%) if you already understand DevOps principles and infrastructure as code; the real value starts with Docker fundamentals. Focus on the Dockerfile instruction details and Compose examples.
- **Deep-read the Kubernetes objects chapters** (~23–39%): The kiosk application deployment example is the book's centerpiece—work through it carefully to see how Pods, ReplicaSets, Services, Secrets, and ConfigMaps combine in practice.
- **Pay special attention to the resource QoS section** (Middle): The BestEffort/Burstable/Guaranteed classification is easy to misunderstand. Note how namespace defaults can override implicit settings—this is a common production gotcha.
- **The networking chapter** (Late) is dense but crucial. If you're not deploying to cloud LoadBalancers immediately, skim the packet-routing details and return when you need to troubleshoot cross-node traffic.
- **The cluster administration chapter** (Late) covers RBAC and authentication—essential for production but skimmable for learning environments. Focus on namespaces and ResourceQuota if you're managing multi-team clusters.
## 【Coverage Limits】
This guide covers the book's progression from Docker basics through Kubernetes core objects, storage, networking, and cluster administration. The excerpts do not cover the final chapters on Kubernetes on AWS and GCP in detail, nor the CI/CD pipeline building sections beyond brief mentions.
##
Passage locations
Excerpt 1
amples of these styles and an explanation of their meaning. Code words in text, database table names, folder names, filenames, file extensions, pathnames, du...
View in text
Excerpt 2
b53ad6559e6705d6f82564baea $ docker run -d --network room \ --network-alias dad --name sleeper alpine sleep 60 b5290bcca85b830935a1d0252ca1bf05d03438ddd22675...
View in text
Excerpt 3
ubectl command by kubectl delete <resource> <resource_name>. Since we have a configuration file on hand, we could also use kubectl delete -f <configuration_f...
View in text
Excerpt 4
her cluster containers. Check out the latest launch time by CREATED column, where we will find that there are three containers that have just been launched:...
View in text
Recommended for You
{{#thumbnailUrl}}
{{/thumbnailUrl}}
{{^thumbnailUrl}}
{{/thumbnailUrl}}
Loading recommended books...
Failed to load, please try again later
Tip the Site
Scan the WeChat Pay or Alipay code to tip. No login required.
WeChat Pay
Alipay